Security Policy
EMA Group is committed to maintaining the security, integrity, and availability of its systems, services, and data.
We take the protection of our customers, partners, and users seriously and encourage responsible disclosure of potential security vulnerabilities that may affect our digital assets or services.
EMA Group develops, operates, and supports advanced technology solutions, including satellite-based tracking and monitoring services provided through the BlueTraker platform and related systems. This policy outlines how security researchers and other parties can responsibly report security issues to us.
Scope of Reporting
We welcome reports of security vulnerabilities that may impact:
- The confidentiality, integrity, or availability of EMA Group systems and services
- Customer or partner data
- Public-facing websites, portals, and APIs
- Authentication, authorization, or access-control mechanisms
Please limit testing to what is strictly necessary to demonstrate the issue.
How to Report a Vulnerability
If you believe you have identified a security vulnerability, please report it responsibly by contacting us at:
- Email: [email protected]
- Subject: Security Vulnerability Report
When submitting a report, please include:
- A clear description of the vulnerability
- Steps required to reproduce the issue
- The potential impact and affected systems
- Any relevant logs, screenshots, or proof-of-concept material
Our Response
EMA Group aims to:
- Acknowledge receipt of vulnerability reports within 5 business days
- Investigate and assess reported issues in a timely manner
- Communicate progress and resolution status where appropriate
We appreciate responsible disclosure and ask that you allow us a reasonable amount of time to address reported issues before any public disclosure.
Responsible Disclosure Guidelines
To ensure the safety and stability of our systems, please do not:
- Perform denial-of-service (DoS) or stress testing
- Access, modify, or delete data that does not belong to you
- Attempt social engineering, phishing, or physical security attacks
- Publicly disclose vulnerabilities before they have been resolved
Legal Notice
This Security Policy is intended to support good-faith security research and responsible disclosure. It does not grant permission to engage in activities that are illegal, unethical, or disruptive. Any testing that violates applicable laws or causes harm to systems, users, or data is strictly prohibited.
Last updated: December 2025
Need help with Tracking and Monitoring Solutions? We are Experts!
Need help with Tracking and Monitoring Solutions? We are Experts!
EMA d.o.o.
Teharje 7B
3000 Celje, Slovenia, EU
EMA d.o.o.
Teharje 7B
3000 Celje, Slovenia, EU
EMA d.o.o.
Teharje 7B
3000 Celje, Slovenia